CrescentHarvest is a malware campaign and associated threat cluster tracked for using Iran protest-themed social engineering to target Farsi-speaking individuals, likely including supporters of anti-government protests, for information theft and longer-term surveillance. The activity has been assessed as consistent with Iran-aligned tradecraft, but public attribution to a specific named nation-state group remains unconfirmed. The operation relies on spear-phishing style delivery using protest-related decoy content in Farsi, including media and written material designed to entice victims into opening malicious shortcut files. Execution chains observed in the campaign use headless console processes, command shell, and PowerShell to extract embedded payloads, display benign decoy content, and reduce user suspicion. Persistence is established through a scheduled task triggered by network connectivity events. A notable feature of CrescentHarvest is DLL sideloading through a legitimate signed executable to launch multiple malicious DLL components. Observed payloads include a browser-focused component that extracts Chrome app-bound encryption material and a second component that functions as a backdoor and information stealer. Reported capabilities include browser credential and cookie theft, collection of browsing history, theft of Telegram Desktop session data, host profiling including security product enumeration, command execution, and keylogging. The malware communicates with command-and-control infrastructure over HTTPS using structured JSON messages and incorporates anti-analysis and dynamic API resolution techniques. Researchers have noted similarities between CrescentHarvest’s scripting and execution flow and earlier Iran-aligned intrusion activity associated by some vendors with Educated Manticore, overlapping with tracking names such as APT42, Charming Kitten, and Mint Sandstorm. Those similarities are insufficient for definitive attribution, and CrescentHarvest is best treated as a distinct tracked campaign with suspected Iranian alignment rather than a conclusively mapped alias of another established cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a named activity cluster amplifying the conflict via phishing, data theft, and server exploitation.
Named as part of the pre-existing APT landscape active prior to Feb 28; associated activity described as phishing, exploitation of public servers, and information theft targeting Israeli, US, and regional networks.
Named activity cluster referenced in Iran-linked pre-conflict cyber campaigns using phishing, server exploitation, and information theft.
Acronis-tracked cyberespionage/surveillance activity using protest-themed Farsi lures delivered via malicious .rar archives containing weaponized .lnk files that extract and persist an info-stealing/backdoor payload; targets appear linked to Iranian dissident monitoring, potentially including dissidents abroad.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.